linux-admin.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* Network accessibility problem
@ 2006-04-07  1:50 gerardo juarez-mondragon
  2006-04-07  7:02 ` Glynn Clements
                   ` (3 more replies)
  0 siblings, 4 replies; 6+ messages in thread
From: gerardo juarez-mondragon @ 2006-04-07  1:50 UTC (permalink / raw)
  To: linux-admin

I have a Fedora Core 2 server running in a
network behind a firewall. I need access to ports
22 and 80 from outside but the firewall
administration is not under my control. I have
requested this access to be opened and the
administrator says it is already open, yet I
still cannot access it from outside.

I have run a few tests and this is what I found:

(Filtering tables are flushed with iptables -F,
on the server, prior to the tests)

I can ping to/from it from/to any place, whether
it is inside or outside the office.

I can ssh to it from any place *inside*, but not
 from outside. A ssh -v from a computer outside
succeeds up to the "entering event loop" message
(which means it has presumably connected but the
dialog does not proceed beyond this point).
Viceversa, attempting a ssh session past the
firewall results in an instantaneous 'Connection
refused' message. The same connection from
another computer succeeds, proving a ssh server
was indeed running at the other end.

telneting to port 80 produces this result:

Trying 207.284.xxx.yyy...
Connected to 207.248.xxx.yyy.
Escape character is '^]'.

when attempted from the (outside) ip authorized
to access the computer. Any other ip just gets to
the 'Trying...' line. This is correct and what
should be happening, yet a browser reports
'request sent' and proceeds no further when
pointed to the address. (The Apache installation
index page should be displayed).

The administrator argues that some 'service'
within my server is blocking packets, but I don't
know that SSH can be configured to restrict
access to specific ip segments. It can restrict
access to *accounts*. Nor that there is such a
service, except the firewall, whose tables I have
already flushed.

Am I missing something? What other tests do you
suggest?

Thanks,
Gerardo




Searching for the best free email?  Try MetaCrawler Mail, from the #1 metasearch service on the Web, http://www.metacrawler.com

^ permalink raw reply	[flat|nested] 6+ messages in thread
* Re: Network accessibility problem
@ 2006-04-07 15:24 Opaschi Octav
  0 siblings, 0 replies; 6+ messages in thread
From: Opaschi Octav @ 2006-04-07 15:24 UTC (permalink / raw)
  To: linux-admin

chuck gelm wrote:
> Dear Gerardo:
>
> You mention only trying one port (ssh:22) from the 'outside'
> and that the ssh attempt failed.
>
> You did not mention that the 'Fedora Core 2 server" (FC2S)
> has a routeable IP address.  What ports of the FC2S are
> reachable from the outside?
>
> HTH, Chuck
>
> -
> To unsubscribe from this list: send the line "unsubscribe linux-admin" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at  http://vger.kernel.org/majordomo-info.html
Chuck, I think that he metioned that only 22 and 80 are accesable from 
outside, but the 22 I doubt it.

Cheers


^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2006-04-07 15:24 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-04-07  1:50 Network accessibility problem gerardo juarez-mondragon
2006-04-07  7:02 ` Glynn Clements
2006-04-07 11:18 ` chuck gelm
2006-04-07 11:54 ` Andreas P. Koenzen
2006-04-07 12:45 ` level
  -- strict thread matches above, loose matches on Subject: below --
2006-04-07 15:24 Opaschi Octav

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).